Step-by-Step Malware Removal Instructions

blockZ Ransomware
Ransomware

blockZ Ransomware

blockZ is a piece of malicious software categorized as ransomware. Our research team discovered this program while inspecting new malware submissions to VirusTotal. After we executed a sample of blockZ on our test system, it encrypted files and appended their filenames with a ".blockZ" extension.

News-fedaka.cc Ads
Notification Spam

News-fedaka.cc Ads

News-fedaka[.]cc displays deceptive content to get permission to show notifications. Also, it redirects to untrustworthy websites. Our team has discovered news-fedaka[.]cc while examining pages that use rogue advertising networks (e.g., illegal movie streaming, torrent sites). News-fedaka[

NB65 Ransomware
Ransomware

NB65 Ransomware

NB65 is ransomware based on another ransomware called CONTI. This malware encrypts files, appends the ".NB65" extension to filenames, and creates the "R3ADM3.txt" file containing a ransom note. It was discovered by Amigo-A. An example of how NB65 renames encrypted files: it changes "1.jpg" to "1.j

InitiatorActivity Adware (Mac)
Mac Virus

InitiatorActivity Adware (Mac)

InitiatorActivity is an application our researchers found while inspecting fake software updaters/installers. After analyzing this rogue app, we determined that it operates as advertising-supported software (adware). InitiatorActivity also belongs to the AdLoad malware family. Adware may

LogicCheck Adware (Mac)
Mac Virus

LogicCheck Adware (Mac)

LogicCheck is an adware-type application that generates advertisements and can read webpage contents and browsing history. We have discovered this application while inspecting deceptive pages offering to install software updates. In most cases, apps like LogicCheck are downloaded and installed u

Solana POP-UP Scam
Phishing/Scam

Solana POP-UP Scam

We have examined this page and concluded that it is a fake Solana website (an identical copy) offering to register for participation in an ignition hackathon and win up to $5 million in prizes. Typically, scams of this kind are promoted via Twitter, Discord, Telegram, and other sites or apps, vari

Whisper Stealer Malware
Trojan

Whisper Stealer Malware

Whisper Stealer is an information stealer targeting Chromium and Gecko browsers, cryptocurrency wallets, Discord tokens, and Telegram sessions (and other data). It is promoted (and sold) on hacker forums. There are five available subscription plans: 250 rubles for one month, 600 rubles for three

ActiveHandler Adware (Mac)
Mac Virus

ActiveHandler Adware (Mac)

ActiveHandler is a rogue application that our researchers discovered while inspecting new submissions to VirusTotal. After analyzing this app, we determined that it operates as adware and is part of the AdLoad malware family. Adware may require certain conditions (e.g., system/browser or

ZombieBoy Trojan
Trojan

ZombieBoy Trojan

ZombieBoy is the name of a cryptomining Trojan that uses the EternalBlue exploit to spread and DoublePulsar backdoor to load and execute its modules. It is used for cryptocurrency mining and remote control. Additionally, it includes an intranet scanner module. ZombieBoy's remote access mod